Use of a Broken or Risky Cryptographic Algorithm Affecting java-1.7.1-ibm-demo package, versions <1:1.7.1.3.0-1jpp.2.el7_1


Severity

Recommended
critical

Based on CentOS security rating.

Threat Intelligence

EPSS
2.8% (85th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS7-JAVA171IBMDEMO-2044851
  • published26 Jul 2021
  • disclosed11 Mar 2015

Introduced: 11 Mar 2015

CVE-2015-0138  (opens in a new tab)
CWE-327  (opens in a new tab)

How to fix?

Upgrade Centos:7 java-1.7.1-ibm-demo to version 1:1.7.1.3.0-1jpp.2.el7_1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream java-1.7.1-ibm-demo package and not the java-1.7.1-ibm-demo package as distributed by Centos. See How to fix? for Centos:7 relevant fixed versions and status.

GSKit in IBM Tivoli Directory Server (ITDS) 6.0 before 6.0.0.73-ISS-ITDS-IF0073, 6.1 before 6.1.0.66-ISS-ITDS-IF0066, 6.2 before 6.2.0.42-ISS-ITDS-IF0042, and 6.3 before 6.3.0.35-ISS-ITDS-IF0035 and IBM Security Directory Server (ISDS) 6.3.1 before 6.3.1.9-ISS-ISDS-IF0009 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.

CVSS Base Scores

version 3.1